FaSQUAL: The BSIA-led Vetting Passport for the UK Security Industry Powered by Neotas Read More →
Generate AI-Powered Audit-Ready Due Diligence Reports instantly. Learn More →
Healthcare Supply Chain Risk

Healthcare Supply Chain Risk: The 2026 Framework That Works

Healthcare supply chain risk explained: risk types, a 5-step management framework, vendor tiering, disruption prevention and contingency planning for providers.

 

192.7M
Individuals affected by the Change Healthcare vendor ransomware attack, per HHS OCR [1]
60%
Of daily US IV solutions came from the single Baxter plant closed by Hurricane Helene, per the FDA [2]
323
Active US drug shortages at the Q1 2024 peak, the highest since ASHP tracking began in 2001 [3]
2x
Annual ransomware attacks on US healthcare organisations more than doubled from 2016 to 2021, per JAMA Health Forum [4]

Quick answer

Healthcare supply chain risk is the exposure a hospital or health system carries when a supplier, distributor or service vendor fails and the failure reaches patient care.

It spans cyberattacks on clearinghouses like Change Healthcare, physical shutdowns like the Baxter IV fluid plant after Hurricane Helene, drug shortages, and compliance failures under HIPAA and FDA QMSR. Managing it takes a supplier inventory, clinical-impact tiering, due diligence, contract controls and tested contingency plans.

Key takeaways

  • The Change Healthcare ransomware attack of February 2024 affected 192.7 million individuals, the largest healthcare data breach recorded by HHS, and it started at a third-party claims vendor rather than a hospital. [1]
  • Physical concentration risk can do more clinical damage than a cyberattack: one flooded Baxter plant in North Carolina produced roughly 60% of the 2.5 million IV solution bags US providers use daily, and the FDA had to authorise temporary imports from 5 overseas facilities. [2]
  • US drug shortages hit an all-time high of 323 active shortages in Q1 2024, and roughly three-quarters of shortages active in 2025 began in 2022 or later, so scarcity is a standing condition rather than a passing event. [3]
  • Healthcare supply chain risk and vendor risk are different disciplines: supply chain risk covers the physical and clinical flow of goods and services, while healthcare vendor risk management covers the data, IT and compliance exposure each individual vendor creates.
  • HIPAA makes supplier failures your failures: 45 CFR 164.308(b) requires written business associate contracts with security assurances before a vendor touches protected health information. [5]
  • A 5-step framework closes most gaps: build a supplier inventory, tier by clinical impact, screen with real due diligence, write enforceable contract controls, and test contingency plans against named scenarios at least twice a year.

What is healthcare supply chain risk?

Healthcare supply chain risk is the probability that a supplier, manufacturer, distributor or service vendor fails in a way that disrupts patient care, breaches regulation or damages the organisation financially. The failure can be a ransomware attack, a flooded factory, a recalled device component, a bankrupt distributor or a sanctioned sub-supplier 3 tiers down.

The defining feature in healthcare is that the downside lands on patients, not just the balance sheet. When a retailer loses a supplier, shelves go empty. When a hospital loses its IV fluid supplier, surgeries get postponed and clinicians ration saline. That difference is why regulators treat healthcare suppliers differently from suppliers in any other industry.

The discipline sits inside a wider set of programmes, and the terms get mixed up constantly. The table below separates them, because the distinction decides who owns the risk and which page of your policy applies.

Discipline What it covers Typical owner Where to go deeper
Healthcare supply chain risk The flow of drugs, devices, consumables and services into care delivery: disruption, shortages, concentration, quality and continuity. VP Supply Chain, COO This guide
Healthcare vendor risk management The data, IT, security and compliance exposure each individual vendor creates, especially vendors touching PHI. CISO, Compliance Healthcare vendor risk management guide
Healthcare third-party risk management The governance programme covering every external relationship: vendors, suppliers, affiliates, contractors and their lifecycle. CRO, General Counsel Healthcare TPRM guide
General supply chain risk management The cross-industry discipline: mapping, assessing and mitigating supplier risk in any sector. Procurement, Risk Supply chain risk management guide

Why are healthcare supply chains so vulnerable?

Healthcare supply chains are vulnerable because production is concentrated, the chain is deep, and demand cannot pause. A single plant produced roughly 60% of the IV solutions US providers use each day, so one flood created a national shortage within a week. [2]

Depth compounds the concentration. A hospital contracts with a distributor, the distributor buys from a manufacturer, the manufacturer depends on an API producer, and the API producer sits in a jurisdiction the hospital has never assessed. Visibility usually stops at tier 1, which is exactly where it stops being useful.

Then there is the demand problem. A hospital cannot defer demand for saline, blood or oncology drugs the way a manufacturer defers a component order. Thin generic-drug margins keep redundancy out of the system, and just-in-time inventory removed the buffer stock that used to absorb shocks.

 

The 6 types of healthcare supply chain risk

Healthcare supply chain risk breaks into 6 categories: cyber, concentration, clinical quality, geopolitical, regulatory and financial. Every major disruption since 2020 fits at least one, and the worst incidents combine 2 or 3 at once.

1. Cyber and data risk

Ransomware and breaches at vendors holding PHI or running clinical and billing systems. Change Healthcare showed one clearinghouse can halt claims for thousands of providers at once.

2. Concentration risk

A single plant, supplier or region carrying a product category alone. One flooded North Carolina facility took out roughly 60% of daily US IV solution supply in 2024.

3. Clinical quality risk

Defective components, contaminated ingredients and recalls that reach patients. FDA QMSR now holds device makers to ISO 13485 purchasing controls for exactly this reason.

4. Geopolitical and tariff risk

Export controls, sanctions, tariffs and regional conflict cutting off APIs, chips and raw materials. Most hospitals cannot name the country their generic APIs come from.

5. Regulatory and compliance risk

Supplier failures that become your HIPAA, FDA or state enforcement problem. A vendor breach without a compliant business associate agreement is a direct covered-entity liability.

6. Financial and integrity risk

Supplier insolvency, hidden ownership, sanctions exposure and fraud. These surface in vendor due diligence and screening, not in delivery metrics.

One observation from our screening work that cuts against the industry’s instinct: budgets treat this as a cyber problem, but the deepest clinical damage of 2024 came from water, not code. The Baxter shutdown postponed surgeries nationwide for months. Most ransomware attacks did not. A programme weighted 90% to cyber controls is defending one of the 6 categories.

What the 2024 to 2026 disruptions proved

Three disruptions between 2024 and 2026 rewrote the risk assumptions for healthcare supply chains: the Change Healthcare ransomware attack, the Baxter IV fluid shutdown and the record run of drug shortages. Each one exposed a different failure mode, and each one was survivable for the organisations that had mapped their dependencies in advance.

Incident Failure mode Documented impact The lesson
Change Healthcare ransomware, February 2024 Cyber, at a services vendor 192.7 million individuals affected, the largest healthcare breach on the HHS OCR portal; claims and billing disrupted for providers nationwide [1] A services vendor can be a bigger single point of failure than any physical supplier. Map revenue-cycle dependencies, not just clinical ones.
Baxter North Cove shutdown, September 2024 Concentration, physical Hurricane Helene closed the plant making ~60% (1.5 million bags) of daily US IV solutions; the FDA declared shortages and cleared temporary imports of 23 products from 5 overseas facilities [2] [6] Ask every category owner one question: if this supplier’s largest site closed tomorrow, who else could supply us, and at what volume.
Drug shortage peak, 2024 through 2026 Structural scarcity 323 active shortages at the Q1 2024 peak, the highest since ASHP began tracking in 2001; 77% of shortages active in 2025 began in 2022 or later [3] Shortage response cannot live in the pharmacy alone. It needs supplier intelligence, substitution protocols and pre-agreed conservation triggers.

The pattern across all 3 is the same. The primary victim was never the only victim, and the organisations that recovered fastest were the ones that already knew which clinical services each supplier fed. That mapping exercise is step 1 of the framework below.

The intelligence gap behind every incident

In Neotas screening engagements, the supplier a hospital knows least about is rarely the software vendor with a completed questionnaire. It is the distributor’s manufacturer, or the manufacturer’s ingredient source. Questionnaires stop at tier 1. Open-source intelligence is how you see past it without waiting for the supplier to volunteer the information.

Which regulations govern healthcare supplier risk?

Four regulatory regimes reach healthcare supplier relationships in the US, and 2 more apply to organisations with EU operations. Each one converts a supplier failure into an enforcement exposure for the provider, which is why supply chain risk in healthcare is a compliance discipline and not only an operational one.

Regulation What it requires of supplier relationships Who it applies to
HIPAA Security Rule, 45 CFR 164.308(b) and 164.314(a) [5] A written business associate agreement with satisfactory security assurances before any vendor creates, receives, maintains or transmits PHI on your behalf. Covered entities and business associates, including subcontractor chains
FDA QMSR, 21 CFR Part 820, effective 2 February 2026 [7] Purchasing and supplier controls under ISO 13485:2016 clause 7.4: supplier evaluation, selection criteria, monitoring and re-evaluation, with records. Our 21 CFR 820 QMSR supplier control guide covers the transition in detail. Medical device manufacturers and their supplier chains
HHS HPH Cybersecurity Performance Goals [8] Voluntary goals that include vendor and supplier cybersecurity requirements and incident planning; increasingly the reference point OCR and payers use to judge reasonableness. Hospitals and health systems
DSCSA, FD&C Act Section 582 [9] Trading only with authorised partners and package-level traceability across the pharmaceutical distribution chain. Manufacturers, wholesalers, dispensers
EU NIS2 Directive, Article 21(2)(d) [10] Supply chain security measures covering relationships with direct suppliers and service providers, for essential entities including the health sector. EU healthcare entities and their suppliers
EU CSDDD, Directive 2024/1760 [11] Human rights and environmental due diligence across the chain of activities for large companies; provisions remain subject to the EU omnibus simplification process, so check current scope before building obligations on it. Large EU and EU-active companies, phased

The practical consequence: your supplier files need to survive an audit under at least 2 of these regimes at once. A HIPAA vendor risk assessment that documents security assurances, and supplier evaluation records that satisfy QMSR purchasing controls, are the 2 files US providers get asked for first.

Neotas | Rated Chartis FCC50

Find the supplier risks your questionnaires missed

Neotas screens healthcare suppliers with open-source intelligence across 200+ languages: sanctions, litigation, adverse media, hidden ownership and integrity risks that self-attestation never surfaces. Analyst-reviewed reports, with a full audit trail for OCR and FDA inspections.

Book a supplier screening walkthrough

 

Healthcare supply chain risk management: the 5-step framework

Healthcare supply chain risk management works in 5 steps: inventory every supplier, tier by clinical impact, screen with real due diligence, write enforceable contract controls, then monitor and test contingency plans. Run the steps in order. Each one depends on the output of the one before it, and skipping the inventory step is the single most common reason programmes stall.

1

Build a single supplier inventory mapped to clinical services

List every supplier, distributor and service vendor in one register: what they provide, which clinical or revenue service depends on them, what data they touch, contract end dates and named alternatives. The mapping to clinical services is the part most inventories skip, and it is the part that decides everything downstream. Pull the initial list from accounts payable, not from procurement’s contract file, because AP catches the suppliers nobody formally onboarded.

2

Tier suppliers by clinical impact and replaceability

Score each supplier on 2 axes: how badly patient care degrades if they fail, and how quickly a substitute can reach the loading dock. A supplier scoring high on both is Tier 1 regardless of contract value. The tiering matrix in the next section gives the full definitions and the assessment cadence each tier earns.

3

Screen suppliers with due diligence that goes past the questionnaire

Questionnaires record what a supplier says about itself. Screening records what the world says about the supplier: sanctions lists, litigation, insolvency signals, regulatory actions, adverse media and beneficial ownership. Tier 1 suppliers warrant enhanced due diligence with analyst review; lower tiers can run on a structured vendor risk assessment template. For vendors touching PHI, fold the HIPAA vendor risk assessment into the same file so one review satisfies both owners.

4

Write contract controls you can actually enforce

Four clauses do most of the work. Security obligations with named controls and audit rights inside the business associate agreement, not vague compliance language. Measurable SLAs: uptime floors, patch windows, fill rates, notification deadlines for incidents and supply interruptions. Renegotiation triggers for tariff shocks, plant closures and ownership changes. Offboarding terms covering data return or destruction, access termination and a closing audit. If a clause has no measurement and no consequence, it is decoration.

5

Monitor continuously and test contingency plans on a calendar

Annual reassessment is a snapshot of a moving target. Tier 1 suppliers need continuous monitoring across integrated sources, with alerts on sanctions changes, litigation, insolvency markers and adverse media between review cycles. Pair the monitoring with contingency tests: tabletop a named scenario twice a year, with the supplier in the room for your top dependencies. The contingency planning section below sets out the scenarios worth running.

The framework plugs into the wider TPRM lifecycle: steps 1 and 2 are the identification phase, step 3 is due diligence, step 4 is contracting, and step 5 is monitoring and offboarding. If your organisation already runs a third-party risk management framework, this is the healthcare supply chain overlay, not a competing programme.

How do you tier healthcare suppliers by clinical impact?

Tier suppliers by asking 2 questions: what happens to patients if this supplier stops tomorrow, and how many days until a substitute delivers at volume. Contract spend is a distraction here. A £40,000 contract for a sole-source surgical consumable outranks a £4 million contract for office services every time.

Tier Definition Examples Due diligence depth Monitoring and testing
Tier 1: Clinical-critical Failure degrades patient care within 72 hours, or no substitute can deliver at volume within 30 days, or the vendor is a single point of failure for revenue cycle. IV fluids, blood products, claims clearinghouse, EHR host, sole-source device components Enhanced due diligence with analyst review, beneficial ownership, site-level concentration check Continuous monitoring; contingency tabletop every 6 months with the supplier involved
Tier 2: Operational Failure disrupts operations or compliance but care continues; substitutes exist within 30 to 90 days. Non-sole-source consumables, lab couriers, scheduling software, facilities contractors with PHI access Structured screening plus questionnaire; HIPAA assessment where PHI is touched Semi-annual review; alert-based monitoring; annual scenario inclusion
Tier 3: Commodity Failure is an inconvenience; substitutes are immediate and interchangeable. Office supplies, general maintenance, catering without patient data Baseline checks at onboarding: sanctions, registration, insurance Annual attestation; re-screen on contract renewal

Two rules keep the tiering honest. First, any supplier that is a single point of failure gets Tier 1 treatment even if its product looks mundane; saline bags looked mundane until September 2024. Second, re-tier on trigger events, not just annually: an acquisition, a plant consolidation or a new sole-source designation changes the answer immediately.

Practice: dual-source the top 20

Qualify a second supplier for your 20 highest clinical-impact items before you need one. Qualification during a shortage takes 3 to 6 times longer than qualification in peacetime.

Practice: check the site, not the brand

Two suppliers can resolve to the same manufacturing site. Concentration hides at plant level, which is where the Baxter lesson lives.

Practice: screen the owners

Sanctions and integrity risk attach to people, not logos. Beneficial ownership screening catches the exposure a company-name check misses. OSINT techniques do this at scale.

Practice: set conservation triggers early

Decide in advance which inventory level triggers clinical conservation protocols for each Tier 1 consumable. Deciding during the shortage costs days you do not have.

Which metrics show the programme is working?

Six metrics tell you whether a healthcare supply chain risk programme works: inventory coverage, single-point-of-failure count, assessment currency, time-to-substitute, contingency test cadence and incident notification speed. Report them to the board quarterly. Activity metrics like questionnaires sent measure effort, and these measure exposure.

Metric What it measures Working target
Inventory coverage Share of active suppliers in the register, mapped to a clinical or revenue service 100% of AP-active suppliers within 12 months of programme start
Single points of failure Count of Tier 1 items with no qualified alternative supplier Falling quarter on quarter, with a named owner per remaining item
Assessment currency Share of Tier 1 suppliers with due diligence completed or refreshed inside the cycle 95%+ current at any point in time
Time-to-substitute Days from Tier 1 supplier failure to substitute delivering at volume, per contingency plan Documented and under the clinical tolerance set for each item
Contingency test cadence Tabletop and simulation exercises completed against named scenarios 2 per year minimum, with findings assigned and closed
Incident notification speed Hours from supplier incident to your team knowing, versus the contractual deadline Within SLA on every tracked incident; misses escalated to contract review

 

How do you build and test supplier contingency plans?

A supplier contingency plan answers 4 questions before the failure happens: which clinical services stop, how long care can tolerate the gap, who supplies the substitute, and who calls whom in the first hour. Write one per Tier 1 supplier. A generic business continuity plan that never names suppliers fails the first time it meets a real shortage.

Set the downtime tolerance clinically, not operationally. Pharmacy can tolerate a 10-day gap in one antibiotic with substitution protocols; the OR cannot tolerate 48 hours without irrigation fluids. Those tolerances, agreed with clinical leadership in advance, are what turn a supplier incident into a managed event instead of a scramble.

Then test against named scenarios. The 3 worth running every year, because each rehearses a different muscle:

Scenario 1: the clearinghouse goes dark

Claims and eligibility down for 21 days. Tests revenue-cycle workarounds, cash reserves, manual claim routing and payer communication. Change Healthcare made this the mandatory scenario.

Scenario 2: the sole-source plant closes

A physical consumable at 60% supply loss for 90 days. Tests conservation triggers, substitute qualification speed, allocation fairness across sites and clinical substitution protocols.

Scenario 3: the supplier fails compliance

A Tier 1 supplier appears on a sanctions list or loses its FDA registration. Tests screening alert speed, legal review, contract exit rights and replacement onboarding under time pressure.

Run each tabletop with procurement, IT, clinical operations and finance in the same room, and bring the supplier in for your top 5 dependencies. Every exercise ends with a findings list, an owner per finding and a close date. An untested plan is a hypothesis; treat the first test as the real draft.

Neotas | Rated Chartis FCC50

Know which of your suppliers is a single point of failure

A Neotas supplier risk review screens your Tier 1 suppliers for sanctions, ownership, litigation, insolvency signals and adverse media, delivered as analyst-reviewed reports your auditors can trace. Scoped to your register, with configurable risk models to match your tiering.

Scope a Tier 1 supplier review

5 mistakes that sink healthcare supply chain risk programmes

The same 5 failures appear across the incidents we study and the programmes we screen for. Each one is cheap to fix before an incident and expensive to explain after one.

1. Tiering by contract spend instead of clinical impact

Spend-ranked registers bury the cheap sole-source consumables that stop surgeries. Saline was nobody’s strategic supplier until September 2024. Rank by what stops when the supplier stops.

2. Treating the questionnaire as the assessment

Self-attestation records the supplier’s opinion of itself. Sanctions exposure, litigation, insolvency markers and ownership changes live in external data, and they change between annual cycles. Verification is the assessment; the questionnaire is the cover sheet.

3. Signing BAAs without enforceable technical terms

A business associate agreement that says “reasonable safeguards” and nothing else gives you no lever when the vendor’s controls turn out to be thin. Name the controls, add audit rights, set incident notification in hours. 45 CFR 164.314(a) sets the floor, not the ceiling.

4. Stopping visibility at tier 1

Your distributor’s manufacturer and the manufacturer’s ingredient source carry your risk whether or not you can see them. Ask Tier 1 suppliers to disclose their own concentration points, and verify what you can through open sources.

5. Writing contingency plans nobody has tested

Plans written for the audit file fail on contact with a real shortage: the substitute’s number is stale, the conservation trigger was never agreed with clinicians, the supplier contact left 2 years ago. Two tabletop exercises a year keep the plan real.

Who owns healthcare supply chain risk, and how Neotas helps

Supply chain risk in a health system has 4 owners, and the programme works when each one gets the intelligence their decisions need. The framework above only runs if these roles share one supplier register and one evidence file per supplier.

VP Supply Chain / COO

Owns the inventory, tiering and continuity plans. Needs concentration analysis and time-to-substitute data per Tier 1 item.

CISO / IT Risk

Owns vendor cyber exposure and BAA technical terms. Needs the supplier register joined to the vendor risk management programme.

Compliance / General Counsel

Owns HIPAA, QMSR and audit readiness. Needs due diligence evidence with a traceable audit trail per supplier.

Procurement / Category leads

Own onboarding, contracts and dual-sourcing. Need screening results before signature, not after.

Neotas supplies the intelligence layer of that programme. We combine structured database checks with open-source intelligence and analyst-led investigation, screening suppliers and their owners across 200+ languages. The table maps what we do to the framework steps above.

Framework step Neotas capability
Step 3: Screening and due diligence OSINT and social media intelligence on suppliers and beneficial owners, sanctions and watchlist checks via premium data sources, adverse media in 200+ languages, and analyst-led enhanced due diligence for Tier 1 relationships.
Step 5: Continuous monitoring Continuous monitoring across our sources with custom alerting, so sanctions changes, litigation and insolvency signals reach you between review cycles rather than at the next annual refresh.
Programme fit and audit Configurable risk models to match your tiering, dashboards for the 4 owner roles, and a full audit trail per supplier that stands up to OCR, FDA and internal audit review.

Neotas | Rated Chartis FCC50

Build a healthcare supplier risk programme that survives its first audit

Talk to our team about screening your supplier register: tiered due diligence, continuous monitoring and analyst-reviewed evidence files, mapped to HIPAA and QMSR supplier control requirements.

Schedule a meeting

 

Healthcare Vendor Risk Management

The companion discipline to this guide: how to assess and manage the data, IT and compliance risk each individual healthcare vendor creates, with programme design for CISOs and compliance leads.

Healthcare Third-Party Risk Management

The governance layer above supplier and vendor risk: building a healthcare TPRM programme covering the full lifecycle from onboarding through offboarding, with roles, policy and board reporting.

HIPAA Business Associate Agreement Guide

What a BAA must contain under 45 CFR 164.314(a), which supplier relationships need one, and the enforceable technical terms that separate a working agreement from compliance decoration.

HIPAA Vendor Risk Assessment

How to run and document a HIPAA-focused risk assessment for vendors handling protected health information, including the evidence OCR expects to see when a business associate is breached.

21 CFR 820 FDA QMSR Supplier Control Guide 2026

The QMSR transition explained for device makers: how 21 CFR Part 820 now incorporates ISO 13485:2016 purchasing controls, and what supplier evaluation records the FDA expects from 2 February 2026.

Vendor Risk Assessment Template

A structured template for assessing vendors and suppliers, covering the risk domains, scoring approach and evidence fields a defensible assessment file needs.

Supply Chain Risk Management

The cross-industry pillar guide: supply chain risk categories, the management process and the frameworks that apply in any sector, of which this healthcare guide is the vertical deep dive.

Supply Chain Risk Assessment

The assessment methodology behind step 3 of the framework: how to score supplier risk across financial, operational, compliance and ESG domains, with an assessment structure you can reuse.

 

Healthcare supply chain risk: frequently asked questions

What is healthcare supply chain risk?
Healthcare supply chain risk is the exposure a hospital or health system carries when a supplier, manufacturer, distributor or service vendor fails in a way that reaches patient care, regulation or finances. Healthcare supply chain risk covers cyberattacks on vendors, physical supply chain disruption like plant closures, drug and device shortages, quality failures, and compliance breaches under HIPAA and FDA rules. It differs from generic supply chain risk management because the failure cost includes clinical harm, not just lost revenue.
What is healthcare supply chain risk management?
Healthcare supply chain risk management is the programme that identifies, assesses and reduces supplier risk across a provider’s supply chain. A working healthcare supply chain risk management programme runs 5 steps: a supplier inventory mapped to clinical services, vendor tiering by clinical impact, supplier due diligence and screening, enforceable contract controls, and continuous monitoring with tested contingency planning. It sits inside the wider healthcare third-party risk management programme and follows the same TPRM lifecycle.
What is the difference between healthcare supply chain risk and vendor risk?
Healthcare supply chain risk covers the flow of drugs, devices, consumables and services into care delivery: shortages, supply chain disruption, concentration risk and continuity across the whole chain. Healthcare vendor risk management covers the exposure one specific vendor creates, usually around data, security and compliance. A hospital manages an IV fluid shortage as supply chain risk and manages the EHR host’s security posture as vendor risk. The 2 programmes should share one supplier register and one evidence file per supplier.
Why are healthcare supply chains so vulnerable to disruption?
Healthcare supply chains are vulnerable because production is concentrated, the chain is deep and demand cannot pause. One plant produced roughly 60% of daily US IV solutions before Hurricane Helene closed it in 2024. Chains run 4 or more tiers deep with supplier visibility usually stopping at tier 1, which is why a supply chain risk assessment has to reach past direct suppliers. And hospitals cannot defer demand for saline, blood or oncology drugs, so there is no slack when supply drops.
What are examples of healthcare supply chain disruptions?
The 3 defining recent examples of healthcare supply chain disruption are the February 2024 Change Healthcare ransomware attack, which affected 192.7 million individuals and disrupted claims nationwide; the September 2024 Hurricane Helene closure of Baxter’s North Cove plant, which cut roughly 60% of US IV solution supply and forced FDA-cleared temporary imports; and the record 323 active US drug shortages tracked by ASHP in Q1 2024. Each fits a different healthcare supply chain risk category: cyber, concentration and structural scarcity.
What caused the 2024 IV fluid shortage in the healthcare supply chain?
Hurricane Helene flooded Baxter International’s North Cove facility in Marion, North Carolina, in late September 2024. According to the FDA, that single plant had produced approximately 60%, around 1.5 million bags, of the IV solutions used daily in the United States. The FDA declared shortages of several solutions and cleared temporary importation of 23 IV and peritoneal dialysis products from 5 overseas Baxter facilities. It is the reference case for concentration risk in the healthcare supply chain.
How do hospitals manage healthcare supply chain risk?
Hospitals manage healthcare supply chain risk in 5 steps: build a supplier inventory mapped to clinical services, tier suppliers by clinical impact and replaceability, screen suppliers with vendor due diligence beyond questionnaires, write enforceable contract controls including BAA security terms and SLAs, and run continuous monitoring with tested supply chain contingency planning. The programme reports 6 supply chain risk metrics to the board, led by the count of single points of failure.
What is a single point of failure in a healthcare supply chain?
A single point of failure in a healthcare supply chain is a supplier, plant or service with no qualified alternative that can deliver at the required volume within your clinical tolerance window. It can be a product like sole-source IV fluids or a service like a claims clearinghouse. Identify them through vendor tiering: for every Tier 1 item, ask who else could supply this within 30 days and at what volume. If the answer is nobody, that item needs a named owner, a dual-sourcing plan and a tested supplier contingency plan.
What is concentration risk in the healthcare supply chain?
Concentration risk in the healthcare supply chain is over-reliance on one supplier, one manufacturing site or one region for a product category. It hides at plant level: 2 apparently separate suppliers can resolve to the same factory, so a category that looks dual-sourced on paper is single-sourced in reality. A supply chain risk assessment that checks manufacturing sites, not just brand names, is how the exposure surfaces. The Baxter North Cove closure, which removed roughly 60% of national IV solution supply, is the reference case.
How does HIPAA apply to healthcare suppliers and the supply chain?
HIPAA applies whenever a supplier creates, receives, maintains or transmits protected health information on your behalf. Under 45 CFR 164.308(b), the covered entity must obtain satisfactory security assurances through a written HIPAA business associate agreement before that access starts, and 164.314(a) sets the required contract terms. The obligation flows down to subcontractors. Document the assurances through a HIPAA vendor risk assessment so the evidence file survives an OCR audit.
What supplier controls does FDA QMSR require from 2026?
From 2 February 2026, the FDA’s Quality Management System Regulation amends 21 CFR Part 820 to incorporate ISO 13485:2016. For the medical device supply chain, that means clause 7.4 purchasing controls: documented criteria for evaluating and selecting suppliers, monitoring and re-evaluation proportionate to the risk the purchased product carries, and records of the evaluations. Device manufacturers need evidence-backed supplier files, not attestations. Our 21 CFR 820 QMSR supplier control guide covers the transition step by step.
What should a healthcare supplier contingency plan include?
A working supplier contingency plan names the clinical services that stop when the supplier fails, the downtime each service can tolerate as agreed with clinical leadership, the qualified substitute and its realistic delivery timeline, the conservation triggers for the affected consumables, and the first-hour contact chain on both sides. Write one per Tier 1 supplier in your healthcare supply chain risk register, and test it in a tabletop exercise at least twice a year against named supply chain disruption scenarios.
What KPIs measure healthcare supply chain risk management?
Six KPIs cover a healthcare supply chain risk management programme: supplier inventory coverage, count of single points of failure, due diligence currency for Tier 1 suppliers, time-to-substitute per Tier 1 item, contingency test cadence with findings closed, and supplier incident notification speed against contractual SLAs. These measure exposure rather than activity, which is what makes them board metrics. A vendor risk assessment template keeps the underlying supplier scoring consistent enough to trend the numbers quarter on quarter.
How does OSINT improve healthcare supplier due diligence?
Open-source intelligence verifies what supplier questionnaires only assert. OSINT techniques surface sanctions and watchlist matches on suppliers and their beneficial owners, litigation and insolvency signals, regulatory actions, and adverse media in local languages that English-only checks miss. Because the sources are external, OSINT also catches changes between annual review cycles, which is when supplier risk actually moves. For Tier 1 suppliers, pair it with analyst-led enhanced due diligence.
Who is responsible for supply chain risk in a hospital?
Ownership of healthcare supply chain risk splits across 4 roles: the VP of Supply Chain or COO owns the inventory, vendor tiering and continuity planning; the CISO owns vendor cyber exposure and BAA technical terms; compliance and General Counsel own regulatory readiness and the audit trail; and procurement owns onboarding, contracts and dual-sourcing. The programme works when all 4 share one supplier register and one evidence file per supplier, governed through the organisation’s third-party risk management framework.

 

References

[1] HHS OCR, Change Healthcare Cybersecurity Incident FAQ (192.7M individuals):
https://www.hhs.gov/hipaa/for-professionals/special-topics/change-healthcare-cybersecurity-incident-frequently-asked-questions/index.html
[2] FDA, Responses to 2023 Intergovernmental Working Meeting on Drug Compounding (Baxter North Cove ~60% / 1.5M bags daily):
https://www.fda.gov/drugs/human-drug-compounding/fda-responses-action-items-identified-2023-intergovernmental-working-meeting-drug-compounding
[3] ASHP / University of Utah Drug Information Service, Drug Shortages Statistics (323 record; 77% began 2022+):
https://www.ashp.org/drug-shortages/shortage-resources/drug-shortages-statistics
[4] Neprash et al., JAMA Health Forum 2022, Trends in Ransomware Attacks on US Health Care Delivery Organizations 2016-2021 (43 to 91 annual attacks; ~42M PHI):
https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9856685/
[5] 45 CFR 164.308 (Administrative safeguards, business associate contracts), eCFR:
https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
[6] FDA Roundup 18 October 2024 (temporary importation of 23 products from 5 facilities):
https://www.fda.gov/news-events/press-announcements/fda-roundup-october-18-2024
[7] Federal Register, Medical Devices; Quality System Regulation Amendments (QMSR final rule, effective 2 Feb 2026):
https://www.federalregister.gov/documents/2024/02/02/2024-01709/medical-devices-quality-system-regulation-amendments
[8] HHS, Healthcare and Public Health Cybersecurity Performance Goals:
https://hphcyber.hhs.gov/performance-goals.html
[9] FDA, Drug Supply Chain Security Act (DSCSA):
https://www.fda.gov/drugs/drug-supply-chain-integrity/drug-supply-chain-security-act-dscsa
[10] EUR-Lex, Directive (EU) 2022/2555 (NIS2), Article 21(2)(d):
https://eur-lex.europa.eu/eli/dir/2022/2555/oj
[11] EUR-Lex, Directive (EU) 2024/1760 (CSDDD):
https://eur-lex.europa.eu/eli/dir/2024/1760/oj

Share:

Picture of Neotas Enhanced Due Diligence

Neotas Enhanced Due Diligence

Neotas Enhanced Due Diligence covers 600Bn+ Archived web pages, 1.8Bn+ court records, 198M+ Corporate records, Global Social Media platforms, and more than 40,000 Media sources from over 100 countries to help you screen & manage risks.

A detailed guide to TPRM and a downloadable checklist to implement the TPRM Framework in 2026

Book a Demo

Explore Neotas Enhanced Due Diligence